Why Therapists Should Never Paste Notes Into Public AI
Pasting session notes into a public AI puts client disclosures in someone else's infrastructure. The ten-second test and what to use instead.

You finish your last session at 6:40. You're three progress notes behind. So you paste a rough summary into ChatGPT and ask it to tighten the language.
I get it. It works. That's the problem.
Every prompt you send to a public model leaves your control the moment you hit enter. Not in a hand-wavy, terms-of-service way. In a literal one: unless you've dug into the settings and turned it off, consumer AI tools can retain what you type and use it to train what they build next. Your client's disclosure, the one they may never have told another living person, is now sitting in someone else's infrastructure.
The test that takes ten seconds
Before typing anything into a public AI, ask one question: would I be comfortable reading this prompt out loud at a licensing board hearing?
A summary with symptoms, family history, and a timeline of disclosures fails that test even with the name stripped out. De-identification is harder than it looks. Three or four specific details is usually all it takes to make someone findable, and clinical notes are nothing but specific details.
And the exposure isn't hypothetical. You're bound by confidentiality obligations that were written long before anyone imagined a chat window that remembers. "The tool was convenient" has never once worked as a defense.
It's worth being concrete about where a prompt actually goes, because the mental model most people carry is wrong. You picture a conversation that evaporates when you close the tab. What can actually happen, depending on the product and the settings you never checked, is retention on someone else's servers, review by someone else's contractors, and incorporation into someone else's next model. None of that requires bad faith by anyone. It's just what the machinery does by default, and defaults are what busy people run on.
Compare that to the disclosure standards you already live by. When you take a case to supervision or consultation, you control the frame: what's shared, with whom, under what obligation. A public chat window offers none of that structure. It's consultation with a counterparty you've never met, under terms you didn't read, recorded forever. Said that way, no clinician would sign up for it. But it doesn't feel like that at 6:40 on a Thursday. It feels like fixing a sentence.
The part nobody names
Here's the thing though. Even if the privacy problem vanished tomorrow, a general model would still be the wrong tool for clinical work.
It doesn't know that your client's presentation shifted after a disclosure three sessions ago. It doesn't know which phrase in your intake notes carries weight only you would recognize. It gives you the response that works reasonably well for most people, because that's exactly what it was optimized to do.
So you get notes that read like a textbook. Competent, generic, and not in your voice. Then next week you re-explain everything from scratch, because the model resets and you don't.
Play that loop forward a year and look at what it costs. Every documentation session starts with you rebuilding context the tool threw away: who this client is, what your orientation is, how you phrase things. You're doing unpaid data entry for a machine that forgets you on purpose. The time you saved on sentence-tightening quietly leaks back out through repetition, and the leak compounds with every client on your caseload.
There's a quieter cost underneath that one. Your notes are your record of care, and over time they become the written history of your clinical thinking. When a general model drafts them, that history slowly stops sounding like you. The phrasing flattens toward the average of every clinician the model ever read. A supervisor reviewing your notes five years from now wouldn't find your voice in them. They'd find the internet's.
Most therapists sense all this and respond with half-measures. Keep the prompts vague. Strip the details. Never name anyone. But vague in means generic out: the less you tell the model, the less useful its draft, so the tool quietly pressures you to share more than you should. That's the trap of general AI for clinical work. Its usefulness and your client's privacy are on opposite ends of the same lever.
What I'd use instead
This is where I'll tell you what we're building, and I'll keep it honest.
An Individual AI is a private model built on one person. Yours is trained on your clinical orientation, your frameworks, and how you actually write, not on client records. You feed it the things that are yours to share: your notes on approach, your training materials, your past writing. It drafts documentation that sounds like you, preps you for sessions, and it never trains anyone else's model. Your data stays encrypted, under your rules, revocable any time.
What it won't do: it's not an EHR, it doesn't replace your documentation system, and it won't think clinically for you. It's the difference between a brilliant stranger and a sharp assistant who has read everything you've ever written about how you work.
Notice what that structure does to the trap from the last section. Because the model is built on your professional materials rather than client records, its usefulness and your clients' privacy stop pulling against each other. The client never has to enter the machine for the machine to be worth using. What it learns is you: how you think about cases in general, how you structure a note, what your theoretical commitments sound like on paper.
And to be clear about how it gets built: reading a few prompts aloud is just the front door (Voice Capture, which is free). The model actually takes shape from everything else you give it. The papers you wrote in grad school. Your supervision notes. The way you answer when it asks you why you chose your orientation. Every conversation you have with it teaches it a little more about how you think, which is something no amount of typing into a public chat window ever accumulates.
So here's the experiment I'd actually run. Upload a few pieces of your own work, a paper, a framework doc, anything that's yours to share, and watch what happens to the output. The before-and-after is the whole argument: generic drafts become drafts in your voice, and each thing you add sharpens it further.
And you can run that experiment without holding your breath, because the terms don't change: your data stays under your control, you can delete all of it at any time, and it never trains public models. That's the power of Authentic Intelligence, and it's easier to see than to explain.
FAQ
Isn't it enough to just be careful about what I type?
Careful helps. But the risk isn't your intent, it's where the words go. A tool that retains prompts is a liability no amount of careful fully closes.
What happens to my data on Uare.ai?
It never trains public models. Encrypted, governed by your rules, deletable when you say so.
Is Voice Capture really free?
Yes. No paid Membership required.
By Kanoa Perman, Chief of Staff at Uare.ai.